Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2021-3447—A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on maEPSS 0.3%CVE-2025-11504HIGHQuickcreator – AI Blog Writer 0.0.9 - 0.1.17 - Unauthenticated API Key ExposureEPSS 0.3%CVE-2024-40596MEDIUMAn issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed inforEPSS 0.3%CVE-2024-40598MEDIUMAn issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (EPSS 0.3%CVE-2025-62705MEDIUMOpenBao and Vault Leak []byte Fields in Audit LogsEPSS 0.3%CVE-2026-20289MEDIUMCisco RoomOS Logging Subsystem Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-38460MEDIUMIn SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartexEPSS 0.3%CVE-2019-0004HIGHJuniper ATP: API and device keys are logged in a world-readable permissions fileEPSS 0.3%CVE-2026-23775HIGHDell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 releEPSS 0.3%CVE-2026-20142MEDIUMSensitive Information Disclosure in "_internal" index in Splunk EnterpriseEPSS 0.3%CVE-2025-10486MEDIUMContent Writer <= 3.6.8 - Unauthenticated Information Exposure via Log FileEPSS 0.3%CVE-2026-20138MEDIUMSensitive Information Disclosure in "_internal" index in Splunk EnterpriseEPSS 0.3%CVE-2024-11193MEDIUMAn information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application EPSS 0.3%CVE-2019-3763HIGHThe RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information eEPSS 0.3%CVE-2024-23210LOWThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.EPSS 0.3%CVE-2026-49088MEDIUMInsertion of Sensitive Information into Log File in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2025-48493MEDIUMYii 2 Redis may expose AUTH paramters in logs in case of connection failureEPSS 0.3%CVE-2024-23840MEDIUM`goreleaser release --debug` shows secretsEPSS 0.3%CVE-2024-38862MEDIUMSNMP and IMPI secrets written to audit logEPSS 0.3%CVE-2024-42407HIGHInsertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authentiEPSS 0.3%